CVE-2021-34249
HIGHOnline Book Store 1.0 - SQL Injection via ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-34249. PoCs published by Moaaz Taha.
AI-analyzed exploit summary This exploit demonstrates a Union-Based blind SQL injection vulnerability in Online Book Store 1.0 via the 'id' parameter. It uses sqlmap to automate the exploitation process to retrieve database information.
Description
SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application URL.
Exploits (1)
exploitdb
SCANNER
by Moaaz Taha · textwebappsphp
https://www.exploit-db.com/exploits/48775
This exploit demonstrates a Union-Based blind SQL injection vulnerability in Online Book Store 1.0 via the 'id' parameter. It uses sqlmap to automate the exploitation process to retrieve database information.
Classification
Scanner 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:
Online Book Store 1.0
No auth needed
Prerequisites:
Access to the target URL · sqlmap installed
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (2)
Core 2
Core References
Exploit, Third Party Advisory, VDB Entry
https://packetstormsecurity.com/files/159000/Online-Book-Store-1.0-SQL-Injection.html
Exploit, Third Party Advisory, VDB Entry
https://www.exploit-db.com/exploits/48775
Scores
CVSS v3
7.5
EPSS
0.0123
EPSS Percentile
65.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-89
Status
published
Products (1)
online_book_store_project/online_book_store
1.0
Published
Feb 24, 2023
Tracked Since
Feb 18, 2026